For most of the past decade, North Korea has occupied a specific role in the crypto industry’s imagination: the attacker. Its state-backed hacking units have been linked to some of the largest thefts in the sector’s history, from the Ronin Bridge to DMM Bitcoin, and blockchain analytics firms consistently attribute the majority of global crypto theft to operators working for Pyongyang. The direction of the money has always been the same, out of foreign exchanges and into the regime.
A report out of Seoul this week describes that direction reversing.
North Korean authorities have arrested a group of former military hackers accused of stealing state funds from two national banks and laundering the proceeds through cryptocurrency, according to Daily NK, an outlet that reports on the country through a network of internal sources. The group allegedly breached the internal systems of the Chosun Central Bank and the Foreign Trade Bank, diverted foreign currency and state trade funds, and moved the money into overseas crypto wallets.
The two institutions are among the most sensitive in the country. The Chosun Central Bank oversees currency issuance and state fund management. The Foreign Trade Bank handles North Korea’s foreign payments and currency transactions, and has long been a focus of international sanctions scrutiny. According to the report, the ring was led by former members of a cyber warfare unit under the Reconnaissance and Intelligence General Bureau, the agency responsible for Pyongyang’s foreign espionage and cyber operations.
In other words, the people accused of robbing North Korea’s banks are the people North Korea trained to rob everyone else’s.
How the Money Allegedly Moved
The most revealing detail isn’t the theft itself. It’s that the laundering route is identical to the one Pyongyang-linked groups use on foreign targets.
After diverting funds from the two banks, the group converted them into cryptocurrency and moved them into wallets outside the country. Chinese brokers then exchanged the assets for US dollars and yuan. Contacts positioned in the border cities of Sinuiju and Hyesan converted the crypto to cash, reportedly in real time, and smuggled the currency back across the frontier.
The operational tradecraft was standard for the units involved. The group split transfers into small amounts to avoid triggering detection thresholds, and communicated using encrypted messaging apps, unregistered phones and Chinese wireless equipment to stay outside monitored networks.
This mirrors the methods documented in multiple sanctions-monitoring reports on how North Korean hacking groups cash out stolen crypto. Chinese over-the-counter traders have been repeatedly identified as the critical chokepoint converting Pyongyang-linked digital assets into usable fiat. What makes this case unusual is the target, not the technique. The infrastructure the regime built to launder money stolen from abroad appears to have worked just as efficiently when pointed at the regime’s own accounts.
Investigators reportedly caught the scheme through banking irregularities rather than blockchain analysis. Officials detected discrepancies in foreign-currency payment approvals alongside suspicious overseas IP activity, and North Korea’s National Intelligence Agency arrested the suspects at a Pyongyang safe house on July 12. The source described news of elite state-trained personnel being involved as having shaken officials in the capital.
What Can and Cannot Be Verified
This story requires genuine caution, and it’s worth stating the limitations plainly rather than burying them.
The account rests on a single anonymous source inside North Korea, relayed through Daily NK. Both CoinDesk and Cointelegraph noted they could not independently verify the report. Reporting on North Korea is uniquely difficult given the absolute control Pyongyang exercises over information, and Daily NK’s internal source network, while long-established, cannot be corroborated in the way conventional reporting can.
No specific exchanges, protocols or wallet addresses connected to this alleged internal theft have been publicly identified. There is no on-chain evidence in the public domain, no confirmed dollar figure for the amount taken, and no official statement from North Korean authorities. Pyongyang has consistently dismissed accusations about its cyber operations as politically motivated fabrications, and it has said nothing about this case.
What can be verified is the surrounding context. North Korean hackers stole a record $2 billion in crypto last year, according to Chainalysis. TRM Labs estimated Pyongyang-linked actors accounted for roughly 76% of all crypto hack and scam losses through April 2026, with approximately $577 million taken in two major incidents this year alone. In June, Consensys, the company behind MetaMask, discovered that a developer linked to North Korea had infiltrated its operations. The capability described in the Daily NK report is entirely consistent with what these units are documented to be able to do.
Why It Matters
If the report is accurate, it carries implications worth thinking through beyond the obvious irony.
The first concerns loyalty. North Korea’s cyber units operate under extreme pressure, with revenue targets and severe consequences for failure. Operators trained in the most advanced intrusion techniques, working in an economy where their skills are worth vastly more than their compensation, represent a persistent insider risk to the state that employs them. An alleged case of state-trained operatives turning those skills on their own government suggests that risk is not theoretical, and the reported reaction among officials in Pyongyang indicates the regime treats it as serious.
The second concerns the China chokepoint. If North Korean insiders can move stolen state funds through Chinese OTC brokers as easily as they move stolen foreign funds, it underscores how central those intermediaries remain to the entire laundering apparatus. Western enforcement has focused heavily on identifying wallets and sanctioning exchanges. This case, if true, points once again to the fiat off-ramp as the more durable pressure point.
The third is more speculative but worth noting. A regime discovering that its own cyber operators can quietly divert funds may respond by tightening internal control over crypto operations, which could change how those units behave abroad. Whether that means more centralised oversight, reduced operational autonomy, or simply harsher internal enforcement is impossible to know from outside.
For the crypto industry, the immediate practical takeaway is limited. No exchange was hit, no protocol was exploited, and no user funds were involved. But the story is a useful reminder of something the industry sometimes forgets: the infrastructure that enables state-sponsored theft is not a state monopoly. It is a set of tools, and tools can be picked up by anyone who knows how to use them, including, apparently, the people who built them.
Disclaimer: This article is for informational purposes only and does not constitute financial or legal advice. Cryptocurrency investments carry significant risk. Always conduct your own research before making any investment decisions.

















